Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #11
Critical command injection flaw disclosed in pi-llm-wiki
Original: CVE-2026-102911: zosmaai pi-llm-wiki (v0.11.0 – 0.11.7) suffers CRITICAL OS command injection in mcp/index.ts. Public ex
A critical vulnerability, CVE-2026-102911, has been disclosed in zosmaai's pi-llm-wiki software, versions 0.11.0 through 0.11.7. The flaw is an OS command injection in mcp/index.ts that could allow remote code execution, and a public exploit is already available. Users are urged to upgrade to version 0.11.8 immediately. Security researchers are sharing the advisory and stressing the urgency given the public exploit code.
Why now: A critical remotely exploitable flaw with a public exploit is circulating, prompting urgent upgrade warnings in the security community.
zosmaaipi-llm-wikiCVE-2026-102911Offseq
Evidence
- CVE-2026-102911: zosmaai pi-llm-wiki (v0.11.0 – 0.11.7) suffers CRITICAL OS command injection in mcp/index.ts. Public exploit available — remote code execution possible. Upgrade to 0.11.8 ASAP. https:// radar.offseq.com/threat/cve-20… · offseq@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/442128